Supply Chain Risk: Your Vendors Have Vendors You've Never Heard Of

Supply Chain Risk: Your Vendors Have Vendors You've Never Heard Of

🎙 Craig Duckworth 👥 192 📅 August 4, 2026 ⏱ 34 min 👁 2 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

third-party risksupply chainOT securityvendor managementcyber insurance

Summary

In this episode of Industrial Cybersecurity Insider, host Craig Duckworth interviews Jowanza Joseph, CEO of Parakeet Risk, about the challenges of managing third-party risk in industrial and critical infrastructure sectors. Joseph, with 15 years of engineering experience at Adobe, Pluralsight, and MasterCard, founded Parakeet Risk to address the underserved industrial sector. The conversation covers the difficulty of cataloging and prioritizing vendors, the hidden layers of subcontractors, and the evolving demands of cyber insurance beyond checkbox questionnaires. They discuss contractual obligations like identifying new OT assets within five minutes, the impact of AI on vulnerability discovery, and the organizational divide between IT and OT security responsibilities. Joseph outlines three hallmarks of a strong third-party risk program: an up-to-date vendor database, a living map of entry points, and a trust center for attestation. They also touch on incident response planning, the role of the CISO in taking responsibility, and the cultural divide between IT and OT teams. The episode concludes with practical starting points for organizations, emphasizing the importance of cataloging vendors and building a culture of collaboration.

176 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its practical, experience-based insights into third-party risk management in industrial settings. Joseph provides a clear framework for starting a risk program, emphasizing cataloging and prioritization. The argumentation is coherent and grounded in real-world examples, such as contractual requirements for rapid asset identification and the challenges of IT/OT integration. However, the discussion lacks quantitative data or specific case studies, relying more on anecdotal evidence and general observations. The argument for why industrial companies must become cybersecurity-focused is persuasive, highlighting the systemic risks and the reputational damage that can occur even if the breach originates from a subcontractor.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the conversation is based on professional experience rather than cited research. The sources mentioned are primarily LinkedIn profiles and company links, which are not academic or authoritative. The title accurately reflects the content, focusing on the hidden layers of vendor risk. The discussion is consistent with known industry trends, but without external references, the reliability is limited to the speakers’ expertise. No comments were provided for analysis.

190 words

Title / Content Match

The title accurately reflects the core theme of the episode, focusing on the hidden layers of vendor risk in supply chains.

Quality & Reliability

7/10

The discussion is grounded in practical experience from an industry insider, but lacks specific data, case studies, or citations to external research. It offers general insights and best practices rather than empirical evidence.

Key Moments

Cited Sources

Concurring Sources

  • NIST Cybersecurity Framework — Provides a structured approach to managing cybersecurity risk, including supply chain considerations.
  • ISO/IEC 27001 — International standard for information security management, often used in vendor assessments.
  • SOC 2 — Trust services criteria for vendor attestation, mentioned in the episode.

Dissenting Sources

  • No discordant sources found — The episode does not present conflicting viewpoints or contradictory information.

Contribution & Novelties

The episode provides a practitioner’s perspective on third-party risk in industrial environments, highlighting the unique challenges of OT systems and the evolving demands of cyber insurance. It offers a practical starting point for organizations, emphasizing the importance of vendor cataloging and the need for IT/OT collaboration. The discussion on contractual obligations for rapid asset identification is particularly timely.

Pour aller plus loin :

  • NIST Cybersecurity Framework — Foundational framework for managing cybersecurity risk, relevant to third-party risk.
  • ISO/IEC 27001 — International standard for information security management, often used in vendor assessments.
  • SOC 2 — Trust services criteria for vendor attestation, mentioned in the episode.
  • CISA’s Cybersecurity Performance Goals — Guidance for critical infrastructure, relevant to industrial cybersecurity.
  • MITRE ATT&CK for ICS — Knowledge base of adversary tactics and techniques for industrial control systems.

133 words

Radar Profile

The radar profile shows balanced scores across information quantity, quality, technical level, and reliability, indicating a well-rounded discussion. The slightly lower technical level suggests the content is accessible to a broad audience, while the reliability score reflects the reliance on expert opinion rather than empirical data.

Reliability 7/10